Lucene search

K
ibmIBM06BBB4664EF2917EFF3C8C7C74BD2FC6CCE136E6577F519278CC89AFC5D5A98E
HistoryApr 03, 2023 - 2:03 p.m.

Security Bulletin: A vulnerability in IBM Spectrum Scale Container Native that could allow an attacker acquiring root privileges on the host (CVE-2022-41736)

2023-04-0314:03:28
www.ibm.com
23
ibm spectrum scale
container native
vulnerability
root privileges
upgrade
openshift container platform

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Summary

A security vulnerability has been identified in IBM Spectrum Scale Container Native that could allow an attacker to acquire root privileges on the host using unshare. A fix for this vulnerability is available.

Vulnerability Details

CVEID:CVE-2022-41736
**DESCRIPTION:**IBM Spectrum Scale contains an unspecified vulnerability that could allow a local user to obtain root privileges.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/237810 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Scale Container Native Storage Access 5.1.2.1 - 5.1.6.0

Remediation/Fixes

For this specific issue, upgrade to IBM Spectrum Scale Container Native v5.1.7.0 or later and OpenShift Container Platform 4.11, or higher.

<https://www.ibm.com/docs/en/scalecontainernative?topic=spectrum-scale-container-native-storage-access-517&gt;

For IBM Spectrum Scale Container Native, see the supported upgrade paths and follow the version specific steps to upgrade to the target version. <https://www.ibm.com/docs/en/scalecontainernative&gt;.

Note:

  • If you are running any version of IBM Spectrum Scale container native < 5.1.5.0, you must first upgrade to 5.1.5.0 before proceeding to a higher version.
  • Non-containerized downloads of Spectrum Scale are available on FixCentral here if you’d like to uplevel the storage cluster to match the Spectrum Scale Container Native 5.1.7.0 level.

If you have issues upgrading to the specified level, contact IBM Service.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmspectrum_scaleMatch5.1.
CPENameOperatorVersion
ibm spectrum scaleeq5.1.

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Related for 06BBB4664EF2917EFF3C8C7C74BD2FC6CCE136E6577F519278CC89AFC5D5A98E